ZyXEL Communications ZyWall 110 User Manual page 1034

Hide thumbs Also See for ZyWall 110:
Table of Contents

Advertisement

• The Zyxel Device supports UDP port 500 and UDP port 4500 for NAT traversal. If you enable this, make
sure the To-Zyxel Device security policies allow UDP port 4500 too.
• Make sure regular security policies allow traffic between the VPN tunnel and the rest of the network.
Regular security policies check packets the Zyxel Device sends before the Zyxel Device encrypts
them and check packets the Zyxel Device receives after the Zyxel Device decrypts them. This
depends on the zone to which you assign the VPN tunnel and the zone from which and to which
traffic may be routed.
• If you set up a VPN tunnel across the Internet, make sure your ISP supports AH or ESP (whichever you
are using).
• If you have the Zyxel Device and remote IPSec router use certificates to authenticate each other, You
must set up the certificates for the Zyxel Device and remote IPSec router first and make sure they trust
each other's certificates. If the Zyxel Device's certificate is self-signed, import it into the remote IPSec
router. If it is signed by a CA, make sure the remote IPSec router trusts that CA. The Zyxel Device uses
one of its Trusted Certificates to authenticate the remote IPSec router's certificate. The trusted
certificate can be the remote IPSec router's self-signed certificate or that of a trusted CA that signed
the remote IPSec router's certificate.
• Multiple SAs connecting through a secure gateway must have the same negotiation mode.
The VPN connection is up but VPN traffic cannot be transmitted through the VPN tunnel.
If you have the Configuration > VPN > IPSec VPN > VPN Connection screen's Use Policy Route to control
dynamic IPSec rules option enabled, check the routing policies to see if they are sending traffic
elsewhere instead of through the VPN tunnels.
I uploaded a logo to show in the SSL VPN user screens but it does not display properly.
The logo graphic must be GIF, JPG, or PNG format. The graphic should use a resolution of 103 x 29 pixels
to avoid distortion when displayed. The Zyxel Device automatically resizes a graphic of a different
resolution to 103 x 29 pixels. The file size must be 100 kilobytes or less. Transparent background is
recommended.
I logged into the SSL VPN but cannot see some of the resource links.
Available resource links vary depending on the SSL application object's configuration.
I cannot download the Zyxel Device's firmware package.
The Zyxel Device's firmware package cannot go through the Zyxel Device when you enable the anti-
virus Destroy compressed files that could not be decompressed option. The Zyxel Device classifies the
firmware package as not being able to be decompressed and deletes it.
Chapter 50 Troubleshooting
ZyWALL USG Series User's Guide
1034

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents